The Perimeter of the Duty: Who Screens, and Under What Authority
Sanctions screening is not an internal policy and not a "compliance requirement" — it is a duty written into the sanctions instruments themselves. In the EU the base instrument for individual measures is Regulation (EU) 269/2014: the funds and economic resources of listed persons are frozen, and no funds may be made available to them directly or indirectly. The addressee is any person within EU jurisdiction, not only a bank. In the United States, blocking flows from IEEPA executive orders and binds all US persons plus any property that comes within the United States. The United Kingdom uses the same architecture — SAMLA 2018 plus regime-specific regulations — with one sharp difference: civil liability is strict, and there is no need to prove knowledge or reasonable cause to suspect, per OFSI's enforcement guidance as updated on 9 February 2026.
The difference between operator types is not whether the duty exists but how dense it is. A bank screens customers at onboarding, the full book at every list update, payer and payee fields in payment messages, correspondent flows, trade finance and securities settlement. An EMI or PSP runs the same payment filter plus an agent network: the agent holds no licence of its own, but its customers are your customers and your exposure. A CASP adds blockchain addresses and the data travelling with the transfer under the Travel Rule. A corporate has a different perimeter altogether: counterparties, ultimate beneficial owners, destination country, commodity codes and shipping route. What they share is one requirement — the filter must fire before execution, not after.
The international layer comes from FATF Recommendations 6 and 7: targeted financial sanctions for terrorism and proliferation financing must be implemented "without delay", which means hours rather than days. From 2027 the EU formalises this through its AML framework as well: Regulation (EU) 2024/1624 (AMLR) expressly requires obliged entities to assess, in their business-wide risk assessment, the "risks of non-implementation and evasion of targeted financial sanctions" — sanctions control formally becomes part of the supervised AML perimeter, mapped in the EU AML package. The industry benchmark for how this is built technically is the Wolfsberg Group's Guidance on Sanctions Screening, which separates two distinct disciplines: customer screening and transaction screening. They are not synonyms — different inputs, different cadence, different failure modes.
Blocking, Freezing and Refusal to Serve: Three Different Processes
Market shorthand collapses these three outcomes into "they blocked it". Operationally they are incompatible, and confusing them is itself a source of breaches.
US blocking. Property in which a blocked person holds an interest becomes unavailable to anyone. Funds move to a segregated blocked interest-bearing account, and returning them to the sender is prohibited — that would be an unlicensed dealing in blocked property. A report goes to OFAC, and the property stays suspended until a licence or a delisting.
EU and UK asset freeze. Funds are frozen where they sit. The account remains the customer's account, the contract survives, interest may be credited — but nothing may be dealt with. The European Commission's asset-freeze FAQ, in its May 2026 revision, further confirms that voting rights attached to a listed person's shares are frozen in full and may not be exercised directly or indirectly, and that the presumption of control is rebuttable case by case. The contrast with the US is structural: the EU and UK freeze the relationship, the US removes the property from circulation.
Rejection. The payment does not touch a listed person but does touch a prohibited sector, good or service. Such a payment is not blocked but rejected, and funds go back to the sender. Reporting forms and deadlines differ, and an operator that blocks "to be safe" what it should have rejected is in breach just as much as one that does the reverse.
| Parameter | United States (OFAC) | European Union | United Kingdom | Switzerland |
|---|---|---|---|---|
| Base instrument | IEEPA plus executive orders, 31 CFR | Regulation 269/2014 (persons), 833/2014 (sectors) | SAMLA 2018 plus regime regulations | Embargo Act, SECO ordinances |
| What happens to the money | Blocked: moved to a blocked account, return to sender prohibited | Frozen in place, account survives | Frozen in place, account survives | Frozen, report to SECO |
| Ownership test | 50% or more, direct or indirect, aggregated; plus substantive control | 50% or more with aggregation, plus a separate control test | More than 50% plus a control test (under review) | Follows the EU logic |
| Extraterritorial reach | Yes: US persons, USD clearing, US-origin goods and software, secondary sanctions | No direct secondary sanctions; anti-circumvention prohibition and country tool | No secondary sanctions; perimeter is UK nexus | None; autonomous implementation |
| Maximum civil penalty | Base amount under 31 CFR 501 App. A; base cap USD 377,700 per violation | Set by each member state; Directive 2024/1226 fixes minimum maxima | Greater of GBP 1m or 50% of the value of the breach | Administrative measures by SECO |
| Criminal exposure | Up to 20 years under IEEPA for wilful breach | At least 5 years under Directive 2024/1226 where EUR 100,000 or more is involved | Up to 7 years' imprisonment | Provided for under the Embargo Act |
Extraterritoriality: US Nexus, the 50% Rule and the Control Question
An operator with no US clients still lives inside the US perimeter if it settles in dollars. Dollar clearing physically passes through a correspondent in the United States, and at that moment a US nexus arises — and with it full OFAC jurisdiction. The same effect comes from US persons in the decision chain and from US-origin technology, software or components. That makes the choice of correspondent chain a sanctions decision rather than an operational one — the mechanics are set out in the piece on correspondent banking and safeguarding.
Secondary sanctions add a second layer. After Rosneft and Lukoil were designated on 22 October 2025 under E.O. 14024, foreign financial institutions came within reach of E.O. 14114: for conducting or facilitating significant transactions involving designated persons, the regulator may close correspondent accounts or impose full blocking sanctions on the institution itself. Formally this is not an obligation on a foreign bank — it is the threat of losing dollar access, which in practice bites harder than any obligation.
The single most consequential change of the past year is the erosion of the 50% Rule's clarity. OFAC's Guidance on Sham Transactions and Sanctions Evasion, published on 31 March 2026, defines sham transactions as transfers that conceal rather than genuinely extinguish a blocked person's continuing interest in property, and lists seven red flags: commercially unreasonable terms, transfers to family members and close associates, unclear business purpose or an inexperienced transferee, unnecessarily complex structures in high-risk jurisdictions, the blocked person's continued involvement in management or use of the property, timing near a designation date, and evasive answers about the blocked person's role. Formally the document supplements the 50% Rule; in substance it converts an arithmetic threshold into a totality-of-the-circumstances test. A holding below half no longer buys comfort.
The EU moved the same way earlier. The Council's updated Best Practices of 3 July 2024 (ST 11623/2024) shifted the threshold from "more than 50%" to "50% or more", confirmed aggregation of holdings across several designated persons, and extended the control criterion to de facto rather than merely legal power, with a list of indicators: a majority shareholding below the threshold, buyback options on favourable terms, share transfers immediately before or after designation, front persons drawn from the family circle, and layered structures using trusts and shells.
The United Kingdom, after the Court of Appeal's judgment in Mints v PJSC National Bank Trust [2023] EWCA Civ 1132, sits in the least comfortable position of the four. The court observed obiter that on a literal reading of the control test, any Russian state entity could be treated as controlled by the President — a conclusion that leads to absurdity. Government responded with joint OFSI and FCDO guidance on public officials, then went further in February 2026: OFSI opened a call for evidence on the ownership and control test, which closed on 20 April 2026. The subject is "hypothetical control" — where a designated person could exercise control but does not — and the same document states that government continues to explore an aggregation model and a shift to "fifty percent or more". Until that change is made in legislation, the UK test remains the least determinate of the four.
What Actually Goes Through the Filter
The object set has long been wider than names. Payment parties — payer, payee, intermediary banks, and the remittance-information fields where vessel and contract names routinely surface. Ultimate beneficial owners — to a depth sufficient to clear the ownership and control test and, since OFAC's March guidance, the sham-transfer test as well.
Vessels are identified by IMO numbers, which survive repainting and reflagging. The EU's 19th package of 23 October 2025 added 117 vessels, taking the shadow-fleet list to 557, and the 21st package of 23 July 2026 added a further 41 and extended the rules to vessels providing support services including bunkering. Aircraft enter the lists by tail number and airframe serial.
Crypto addresses sit in the SDN List as a distinct record field, across Bitcoin, Ethereum, Tron and other networks. The instructive case is the designation of the Garantex exchange, its successor Grinex and the surrounding network on 14 August 2025: Treasury cited more than USD 100 million in transactions linked to illicit activity since 2019 and USD 26 million in crypto assets frozen by the US Secret Service on 6 March 2025. The practical lesson for a CASP: an address match is the start, not the end — risk carries one or two hops out from a designated address, and static list matching will not catch it.
Goods and tariff codes. The joint Common High Priority Items List, maintained by the United States, the EU, Japan and the United Kingdom, contains 50 items identified by six-digit HS codes across tiers 1, 2, 3.A, 3.B, 4.A and 4.B — from integrated circuits to machine tools and test equipment. For a payment operator this means the invoice contents are screened, not just the counterparty name; the goods perimeter is unpacked in the piece on goods under EU sanctions. Geography and IP close the loop: country of incorporation, country of actual presence, country of app login.
Where the Technology Breaks: Matching, False Positives, Windows
Screening is fuzzy string comparison, and its pathologies are predictable. A Cyrillic name can be transliterated a dozen ways; Arabic and Chinese names spread wider still; name-element order is not universal. In its information paper Strengthening AML/CFT Name Screening Practices (April 2022), MAS calls the absence of fuzzy logic and reliance on exact matching a control defect, and separately states that differences in names arising from translation — the regulator's example is Chen versus Tan — cannot justify closing an alert.
The price of tuning the other way is false positives. No regulator publishes consolidated statistics, and the industry figures of "95–99% false" circulate without a primary source. The one verifiable anchor comes from an ECB paper on screening and instant payments: at most banks, between 3% and 15% of payments generate alerts requiring manual review. The same paper records a conflict that tuning cannot solve — alert review needs a human, and that always takes longer than the maximum execution time of an SCT Inst instant transfer. Instant payments and manual verification are incompatible by construction.
Update cadence and windows. OFAC changes the SDN List on any business day without a schedule; the EU publishes changes in the Official Journal with immediate effect; Switzerland runs on its own lag — SECO adopted the 20th package listings only on 22 May 2026, nearly a month after the EU, while deferring the substantive financial and trade measures of the same package. Between publication and load into the screening engine there is always a window, and it should be measured in hours.
Retro-screening. After every package the book is rescanned: a customer clean yesterday is designated today. Separately, a lookback across executed transactions is needed — that is what surfaces the breaches that later become voluntary disclosures. Batch versus real-time is not a choice but two mandatory modes: a real-time transaction filter and a regular batch sweep of the customer base between periodic reviews, which MAS expects explicitly.
How this fails in practice is shown by the GBP 160,000 penalty against Bank of Scotland: the automated system failed to recognise a spelling variant of a designated individual's name and the payment went through. The lessons OFSI drew publicly read as a tuning checklist — configuration must cover spelling and transliteration variants; automation cannot be relied on without explicit contingency procedures; training material must be refreshed against a changed risk geography; and voluntary disclosure, made here within two weeks, genuinely reduces the penalty.
Enforcement: The Numbers That Set Risk Appetite
Three years of US data show not more cases but bigger ones. OFAC's 2024 record shows 12 actions totalling USD 48,790,404, the largest being SCG Plastics at USD 20,000,000 and Aiotec GmbH at USD 14,550,000. In 2025 there were 14 actions totalling USD 265,746,819, of which GVA Capital Ltd. alone accounted for USD 215,988,868. For 2026 to 12 August: 6 actions totalling USD 282,718,425, with Adani Enterprises Limited on 18 May 2026 at USD 275,000,000. The crypto segment sits on its own line: Exodus Movement at USD 3,103,360 and ShapeShift AG at USD 750,000.
The penalty arithmetic is set by Appendix A to 31 CFR Part 501. For a non-egregious case with voluntary self-disclosure the base amount is one-half of the transaction value, capped at USD 188,850 per violation; without disclosure it is the schedule amount, capped at USD 377,700; for an egregious case with disclosure it is half the applicable statutory maximum, and without disclosure the full maximum. A disclosure is not voluntary if a third party has already reported the breach, if it is materially incomplete, or if it is made without senior-management authorisation.
The United Kingdom has recalibrated its incentives. OFSI's guidance as updated on 9 February 2026 cut the voluntary-disclosure discount from 50% to 30%, adding 20% for settlement within 30 business days with a waiver of appeal rights and up to 20% under the Early Account Scheme. Fixed penalties of GBP 5,000 and GBP 10,000 now apply to information, reporting and licensing offences. The maximum remains the greater of GBP 1 million or half the value of the breach; doubling it to GBP 2 million or the full value has been announced but requires parliamentary approval, so until then the existing formula is the one to model. The scale of the workload appears in the OFSI Annual Review 2024–25, published on 15 October 2025: 394 reports of suspected breaches, 329 of them under the Russia regime, 214 cases closed, 904 specific licensing decisions and 19 general licences. OFSI's Strategy 2026–29, published on 15 April 2026, promises published KPIs starting with the autumn review.
The EU criminalised sanctions breaches centrally. Directive (EU) 2024/1226 of 24 April 2024, with a transposition deadline of 20 May 2025, requires minimum maximum penalties: at least five years' imprisonment for making funds available to designated persons and for concealment where EUR 100,000 or more is involved, at least five years for military and dual-use goods regardless of value, at least three years for travel-ban breaches, and at least one year for reporting failures. For legal persons: 1% of worldwide turnover or EUR 8 million for reporting offences and 5% or EUR 40 million for the rest. A separate provision extends criminal liability to serious negligence in respect of military and dual-use goods, which lands directly on professional intermediaries. Implementation is thinner than the text: on 24 July 2025 the Commission opened infringement proceedings against 18 member states that had not completed transposition, Germany, France, Italy, Spain, Ireland and Cyprus among them. As of August 2026 there is still no single European enforcement standard.
The Russia Programme as the Stress Test — and the Over-Compliance Problem
The Russia regime is where screening architecture is tested hardest, because it changes on a quarterly cadence and reaches deeper into ownership, crypto and shipping than any other programme. Current as at this article is the EU's 21st package, adopted on 23 July 2026 and given effect, for the sectoral measures, by Council Regulation 2026/1848. It contains 218 listings — 48 individuals and 170 entities, the largest batch in four years; asset freezes on 94 banks and major financial institutions; transaction bans extended to a further 33 Russian credit and financial institutions; and transaction bans on 14 crypto-asset service platforms across Georgia, Panama, the UAE, the Marshall Islands, Kyrgyzstan and Belarus. The structural novelty is a power to ban crypto-asset services from an entire third country whose providers are systematically used for circumvention; no country has been designated under it yet. The oil price cap's automatic adjustment mechanism is paused until 15 July 2027, and derogation deadlines for divesting Russian assets are extended to 31 December 2027.
The preceding 20th package of 23 April 2026 introduced a sectoral ban on dealings with crypto-asset service providers established in Russia and with decentralised platforms, prohibited the rouble-backed stablecoin RUBx and the digital rouble, took the number of banks cut off from the EU market to 70, and activated the anti-circumvention tool at country level for the first time, against Kyrgyzstan. The 19th package, back in October 2025, banned dealings in the A7A5 stablecoin and with the Mir card scheme and the Faster Payments System.
Three provisions of Article 5b of Regulation 833/2014 set the practical perimeter for private individuals. First, the deposit ceiling: an EU credit institution may not accept deposits exceeding EUR 100,000 per institution from Russian nationals, persons resident in Russia or entities established in Russia. Second, a prohibition on crypto-asset services as defined in MiCA, on issuing payment instruments, on acquiring, on payment initiation and on issuing electronic money for the same categories. Third, the carve-out: neither provision applies to nationals of EU, EEA or Swiss states, nor to holders of temporary or permanent residence permits in those states.
The live conflict sits exactly on the edge of that carve-out. The European Commission's FAQ on payment services of 13 March 2026 removed some of the ambiguity: access to online and mobile banking, direct bank transfers and cash withdrawals fall outside the prohibition; existing debit and credit cards need not be cancelled or frozen, but renewal and re-issuance count as new issuance and are prohibited for in-scope persons; holders of long-stay Type D visas who have completed residence-registration formalities are normally treated as legally resident; and the restrictions bind Russian nationals, residents and Russian entities, but not non-Russian companies merely because Russians own them.
The gap between that text and market practice is over-compliance. The law prohibits a defined set of services for a defined set of persons. A bank that closes an account on the basis of a passport, refuses a holder of a valid residence permit, or freezes funds while a permit is being renewed is acting on its own risk policy, not on a sanctions provision. Legally that is its prerogative: the relationship is contractual, and refusal to serve is not a sanctions measure. Practically the outcome is the same either way — and the second cannot be challenged on sanctions grounds. The mechanics are set out in the pieces on account closure and de-risking and on choosing a booking centre. A separate layer is the payment corridors outside the dollar and euro perimeter: why Chinese banks apply their own, still more conservative filter is covered in payments with China.
What a Sanctions Programme Physically Consists Of
The skeleton is set by the Framework for OFAC Compliance Commitments: management commitment, risk assessment, internal controls, testing and auditing, and training. This is the minimum all four regulators in the table above look for, and the baseline from which penalty mitigation is calculated.
The sanctions risk assessment is a standalone document, not a section of the AML risk assessment. It records customer segments by nationality and residence, settlement currencies and the nexus each creates, the correspondent chain, product lines mapped against Article 5b, distribution channels and the agent network, and geographies. Matching thresholds are calibrated from it, not the other way round.
Tuning and provability. Fuzzy-match thresholds, transliteration scheme coverage, handling of list entries without structured identifiers, an alert-review procedure with SLAs, retro-screening after every update and lookback across executed transactions — all of it must be documented, tested and reproducible. The absence of a configuration log is a defect in itself: in the Bank of Scotland case OFSI penalised not the miss as such but the fact that the control did not work.
Licences. Not everything prohibited is prohibited permanently. OFAC issues general licences, self-executing for anyone meeting the conditions, and specific licences on application; OFSI licenses on grounds set out in each regime's regulations. Across 2024–25 OFSI took 904 specific licensing decisions and issued 19 general licences. Working with a licence is a normal operational route, not an admission of fault.
Voluntary disclosure and escalation. The arithmetic is explicit: in the US disclosure halves the base amount, in the UK it earns up to 30%, which stacks with 20% for settlement and up to 20% under the Early Account Scheme. The decision to disclose belongs at board level and on a timescale measured in days. Training is not an annual slide deck: OFSI expressly cited stale training material as a contributing factor to a breach. How this block joins the rest of a licensed operator's perimeter is shown in the compliance stack and in the piece on banking for a licensed operator; anyone operating under someone else's regulator should note that sanctions liability does not come with the rented licence, and the map of regimes by jurisdiction sits in the financial licences overview.
Why the Payment Is Stuck and What to Do
First, your own bank is almost never the one holding it. In a dollar chain the decision belongs to a US correspondent with whom you have no relationship at all. Your bank is waiting for an answer too, and often does not know the grounds. The same applies in euro where an intermediary institution in another country sits in the chain.
Second, the right to an explanation is limited by design. The operator is required not to disclose the fact and content of a report to the regulator, and sometimes not to detail the freeze itself. Demanding to be shown who and why is unproductive; what works is establishing which institution in the chain holds the funds and under which regime, and obtaining a status confirmation from your operator to support a subsequent licence application.
Third, timing. A freeze has no term — it lasts until delisting or a licence. Clearing a false-positive alert takes hours to a few business days. A refusal to serve on risk-policy grounds is not a procedure but a decision, and is contestable only in contract.
Fourth, delisting. In the US the process is set out in 31 CFR 501.807: a petition goes through the reconsideration portal, OFAC checks completeness in 7–10 business days and then issues a questionnaire, usually within 90 days; total duration is not fixed and is measured in years. In the EU listings are reviewed periodically and challenged before the General Court. The UK provides for ministerial review followed by judicial oversight. Recent packages show delisting is achievable: in the 20th package the EU removed 11 vessels and 5 third-country financial entities after they gave compliance undertakings. The adjacent question — how the sanctions filter interacts with ordinary source-of-wealth review — is covered in AML/KYC for the private client.
Calendar: What Is Already Scheduled
| Date | Milestone |
|---|---|
| 20 May 2025 | Transposition deadline for Directive (EU) 2024/1226 criminalising sanctions breaches |
| 24 July 2025 | Commission opens infringement proceedings against 18 member states over incomplete transposition |
| 23 October 2025 | EU 19th package: A7A5, Mir and the Faster Payments System, 117 vessels (557 in total) |
| 9 February 2026 | Revised OFSI guidance: voluntary-disclosure discount cut from 50% to 30% |
| 31 March 2026 | OFAC Guidance on Sham Transactions: the 50% Rule supplemented by a totality test |
| 20 April 2026 | OFSI call for evidence on the ownership and control test closes |
| 23 April 2026 | EU 20th package: sectoral ban on Russian CASPs, RUBx and the digital rouble |
| 23 July 2026 | EU 21st package: 218 listings, 94 banks, power to ban a third country's crypto services |
| Autumn 2026 | OFSI Annual Review with the first published KPIs under the 2026–29 strategy |
| 1 January 2027 | Restrictions on servicing LNG terminals take effect (21st package) |
| 10 July 2027 | AMLR applies: assessing risks of non-implementation and evasion of targeted financial sanctions becomes mandatory |
| 15 July 2027 | Pause on the oil price cap's automatic adjustment mechanism expires |
| 31 December 2027 | Extended EU derogations for divesting Russian assets expire |
| 2028 | AMLA moves to direct supervision of selected obliged entities |
Q/A
Why is a payment stuck when neither party is on any list
Screening compares strings fuzzily, and a match on a spelling variant, a transliteration or part of a vessel name in the remittance field generates an alert. ECB data indicates that at most banks between 3% and 15% of payments generate alerts requiring manual review, and the overwhelming majority of those are false. The second common cause is sector or goods: the payment involves no listed person but touches a prohibited category, in which case it is not blocked but rejected and returned to the sender. The third is the chain: in dollar settlement the decision belongs to a US correspondent to whom you are not a customer.
What is the practical difference between US blocking and an EU freeze
In the US the property is moved to a segregated blocked account and cannot be returned to the sender — that would itself be a dealing in blocked property. In the EU and UK funds are frozen where they sit: the account remains the customer's, the contract survives, interest accrues, but nothing may be dealt with, and voting rights attached to shares are frozen in full. For an operator these are different processes, different reporting forms and different deadlines. For a client the practical difference is that a European freeze is lifted by a licence or a delisting without the money moving, whereas the US version requires a separate authorisation for any movement at all.
Can an EU bank close an account solely because of Russian citizenship
Not under the sanctions rules. Article 5b of Regulation 833/2014 prohibits deposits above EUR 100,000, crypto-asset services, the issuance of payment instruments, acquiring and the issuance of electronic money, but expressly carves out nationals of EU, EEA and Swiss states and holders of temporary or permanent residence permits. The Commission's FAQ of 13 March 2026 further confirmed that online banking, transfers and cash withdrawals fall outside the perimeter, that existing cards need not be cancelled, and that Type D visa holders with completed residence registration are treated as legally resident. A bank may nonetheless exit the relationship under its own risk policy — that is over-compliance, and it is contested in contract, not under sanctions law.
Is it worth disclosing a breach yourself
The arithmetic is explicit. In the US, for a non-egregious case voluntary self-disclosure reduces the base amount to one-half of the transaction value capped at USD 188,850 instead of USD 377,700, and for an egregious case to half the applicable statutory maximum. In the UK, since 9 February 2026 the disclosure discount is 30% rather than 50%, but it stacks with 20% for settling within 30 business days and up to 20% under the Early Account Scheme. A disclosure stops being voluntary if a third party has already reported the matter, if it is materially incomplete, or if it lacks senior-management authorisation — which is why the decision is taken quickly and at board level.